Privacy Policy
Last updated: 6 September 2026
This is an informational translation. The binding version is the Czech original — Ochrana osobních údajů.
This document says what we know about you and about the visitors of your site, who gets to see it and how long we keep it. We wrote it so things can be found in it, not so it looks legal.
1. Who the controller is
The controller of personal data is Ondřej Smutný, company ID 75343533, registered at Družstevní 511, 294 41 Dobrovice, Czech Republic. Contact for anything to do with data protection: info@webeas.com. We are not required to appoint a data protection officer and do not have one.
2. Two different roles
In a service where customers build their own websites there are always two separate sets of data:
- Your data as a user — account, payments, support conversations. Here we are the controller and sections 3 to 5 apply.
- Data of your site’s visitors and customers — form messages, bookings, orders, newsletter subscribers, reviews, cookie consents, analytics. Here we are the processor and you are the controller; we do with the data only what you instruct. Section 6 covers it.
This policy also serves as the processing agreement under Article 28 GDPR: it defines the subject and duration of processing, the types of data, our obligations (confidentiality, security, assistance with data subject requests, deletion on instruction) and the list of other processors in section 8.
3. Data we process as controller
| What | Why | Legal basis |
|---|---|---|
| Name or company name, email, password (stored in an unreadable form) | Running the account and the service | Performance of a contract |
| Subscription and payment details (what you bought, when, for how much) | Billing and accounting | Contract and legal obligation |
| The content of messages you send us | To answer you and keep a record of what was agreed | Legitimate interest |
| Sign-in details from Google when you use the “Continue with Google” button (name, email, account identifier and profile picture) | Creating and signing in to the account without setting up another password | Performance of a contract |
| Operational records (sign-ins, errors, IP address) | Securing the service and finding faults | Legitimate interest |
| Account activity — sign-ins, security changes, publishing and restores (time, kind of device; no IP address) | So you can tell whether someone else got into the account; kept for 180 days | Legitimate interest |
| Transactional emails (address verification, module notifications) | Running the service | Performance of a contract |
We do not process your payment card and never see it — the card number stays with the payment gateway (section 8).
Signing in with Google is optional — an account works just as well with an email and a password. If you use it, Google learns that you use Webeas and passes us your name, email address, account identifier and profile picture. Your Google password never reaches us. You can undo the link any time in your Google account settings and sign in with an email and password instead. Google acts as a separate controller here and follows its own policy.
4. The contact form on webeas.com
When you write to us through the form on this site, we receive your name, email, the chosen topic and the message. A confirmation that the message arrived is sent to that address. We use the address only to reply — you are not added to any mailing and it is not passed on.
To protect against bots we attach the sender’s IP address to the delivered message and keep a counter of sent messages against it for one hour. Nothing else is derived from it and the counter expires after that hour. The form also uses the Cloudflare Turnstile visitor check, which does not track across sites and stores nothing in your browser. Legal basis: legitimate interest in handling the enquiry and securing the form; for people interested in the service, steps prior to entering into a contract.
5. Newsletter and commercial messages from us
We send marketing emails only to people who asked for them, and each one can be unsubscribed with a single click. Operational messages about your account — subscription ending, failed payment, an outage — are not commercial messages and arrive without consent, because the service would not work without them.
6. Data we process for you
Depending on which modules you switch on, data about your visitors also passes through our service. There, you are the controller — you decide what is collected and why, and you are responsible for informing visitors and for the legal basis. We store the data, deliver it and make it available to you; we do nothing else with it.
| Module | What passes through it |
|---|---|
| Forms | Whatever a visitor fills in; bot protection |
| Bookings | Name, contact, time, note; confirmations and reminders by email |
| Selling | Buyer’s email and name, amount, order status; payment goes through your gateway |
| Invoicing | Customer details on the document, entered by you |
| Newsletter | Subscriber’s email and proof of consent: time and IP address of sign-up |
| Reviews | Name and text submitted by a visitor |
| Cookie banner | A record of consent — see section 7 |
| Analytics | Traffic without cookies — see section 7 |
| AI assistant | Visitor messages, which go to the model provider |
We delete this data on your instruction, and at the latest when the site or account is deleted (section 10). We do not look into your modules: access to the content of your data is limited to authorised persons, and only where it is needed to fix a fault you have reported.
7. Cookies, analytics and consent
The admin and this site
The admin uses only the technical cookies needed for signing in. The webeas.com marketing site uses no tracking or advertising cookies from third parties.
How we measure traffic on customer sites
The Analytics module is built so that basic measurement needs no consent: it collects aggregate numbers only — how many views a page had on a given day, where the visit came from, the device, browser and country. It stores nothing in the visitor’s browser and without consent their IP address is not read at all.
Extended measurement (unique visitors, time on site, bounce rate) only starts once a visitor agrees to statistics in the cookie banner. Even then the IP address is not stored: it only feeds a one-way fingerprint that changes every day, so a visitor cannot be followed across days.
The record of consent
The Cookies module stores proof of each consent in case of an inspection: a random consent identifier, which categories were allowed, the version of the banner text, the language and the time. There is no IP address in it — proving consent does not need one. A visitor can change or withdraw consent at any time using a link on the site.
8. Who we pass data to
We do not sell data and do not pass it on for advertising. We do use suppliers who act as our processors:
| Who | What for | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting, network, file storage, bot protection for forms, image generation, template previews, domain management | EU |
| Neon, Inc. | Database | EU (Frankfurt) |
| Resend (Plus Five Five, Inc.) | Sending emails — both operational and newsletters | EU / USA |
| Anthropic PBC | Language models for artificial intelligence features (section 9) | USA |
| Stripe (Stripe Payments Europe, Ltd.) | Payments for our service and payments from your customers | EU / USA |
| Unsplash Inc. | Stock photos — only the search term leaves, no personal data | USA |
Depending on what you switch on yourself, others may join: Google (reCAPTCHA on a form, the map in the Find us module, or signing in with a Google account), sending tools such as Ecomail, SmartEmailing, MailerLite or Mailchimp, the invoicing service Fakturoid, or Netlify hosting for a site export. Those services run on your accounts with your keys; their processing follows their own terms.
Transfers outside the EU rely on the European Commission’s standard contractual clauses, or on an adequacy decision. For sites with the Cookies module enabled, the list of processors is added to that site’s own policy automatically on every publish, so it cannot go stale.
9. Artificial intelligence features
When you start a feature marked as AI — building a page or a section, editing copy, design suggestions, SEO descriptions, translation, replying to a review, the editor assistant — we send the necessary text to Anthropic PBC for processing. That is typically the content of the page being edited, the site name and your business profile if you have filled it in. For the design check, a screenshot of the page in progress is sent as well.
Anthropic acts as our processor under an agreement for business customers and this data is not used to train models. We do not send personal data of your site’s visitors or the content of form messages — unless you put them into the prompt yourself.
Image generation runs on Cloudflare infrastructure and the prompt does not leave the processors listed above. Removing a background or an unwanted object from a photo runs directly in your browser — the photo is not uploaded anywhere; only the model itself is downloaded (from the public jsDelivr and Hugging Face repositories).
If your site has the AI assistant for visitors enabled, visitor messages also go to Anthropic. You are the controller of that data; the assistant window stores nothing on the visitor’s device.
10. How long we keep data
| What | How long |
|---|---|
| Account data and site content | For as long as the account exists; deletion is immediate and irreversible |
| Accounting documents | For the period required by law, even after the account is closed |
| Backups before publishing | Depends on your plan |
| Page versions | The last 20 of each page |
| Backup of the original photo | 30 days from upload |
| A photo deleted in the bin | 30 days from deletion, then irreversibly; does not apply to closing an account or site |
| Weekly backup of account content | Depends on your plan |
| Copies of uploaded files | For as long as the site exists |
| Analytics — identifiers | 425 days |
| Analytics — aggregate numbers | 770 days |
| Sessions in progress in analytics | 2 days |
| Cookie consent records | Until the site is deleted; used to prove consent |
| Messages from the contact form on webeas.com | At most 12 months after the enquiry is handled |
| Counter for form bot protection | 1 hour |
Deleting an account or a site is immediate and irreversible — there is no bin and no cooling-off period. If you want to keep your data, export it beforehand; the export of the whole account is in the admin. A free site nobody uses is retired by the process described in the terms of service, always with an email warning in advance.
11. Security
Data is always transmitted encrypted (HTTPS). Passwords are stored in an unreadable form from which the original cannot be recovered. Access keys to third-party services you entrust to us are stored encrypted. Access to production data is limited to the operator.
Should a breach happen that poses a risk to you, we report it to the supervisory authority within 72 hours and tell you as well.
12. Your rights
You have the right of access to your data, to rectification, erasure, restriction of processing and to portability. You may object to processing based on legitimate interest; any consent you have given can be withdrawn at any time, without affecting the lawfulness of earlier processing.
Most of it you can do yourself in the admin — edit account details, export data and delete the account without asking. For the rest, write to info@webeas.com; we reply within one month at the latest.
If you are a visitor or customer of a site built on Webeas, please contact the operator of that site — they are the controller of your data. If you cannot reach them, write to us and we will pass it on.
You may lodge a complaint with the Czech Data Protection Authority, Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz.
13. Changes to this policy
The service evolves and so does this document. You will hear about significant changes by email at least 14 days in advance. The date of the last change is given at the top.